Security Event 4733 help sentinel Log analytic work space

Minghui Zou 186 Reputation points
2021-12-16T08:39:50.707+00:00

Hi community experts!

I had trouble with the following issue. we have connected security events via OMS agent to Log analytic workspace. but we found something really interesting.

for security event log 4733, which is a user is removed from the AD, in the event viewer you can see the account name that is being removed! but in the LAW

we can not see the account that is being removed. we belived we have found similar issue.

https://techcommunity.microsoft.com/t5/microsoft-sentinel/security-event-4732-and-4733-is-missing-details/m-p/3033075

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,065 questions
{count} votes